CHAPTER 1
A
RESILIENT
INFRASTRUCTURE
The Government will work with key stakeholders - the CII operators
and the cybersecurity community - in four major areas.
We will:
Step up the protection of our essential services. We will implement
a CII Protection Programme which emphasises robust and systematic
cyber risk management processes, and the importance of a culture
of cyber risk awareness across all levels of CII organisations. We will
increase the adoption of Security-by-Design practices to address
cybersecurity issues upstream and along the supply chain.
Enhance our capability to respond decisively to cyber threats.
We will enhance our national cyber situational awareness and
conduct regular multi-sector cybersecurity exercises with more
complex scenarios and involving more and more sectors. We will
build up more National Cyber Incident Response Teams (NCIRT)
and enhance the Disaster Recovery Plans (DRP) and Business
Continuity Plans (BCP) of the critical sectors.
Behind the scenes, in every city (and Singapore is no exception),
a gamut of essential services and infrastructure are needed to
keep a modern metropolis running smoothly. Essential services
such as energy, banking, healthcare and transport are powered
by infocomm technology. Cyber-attacks on these Critical Information
Infrastructures (CIIs) can interfere with these essential services.
At best, they lead to inconveniences. At worst, they can result in
significant disruptions to the economy and to our society.
The effects of a cyber-attack on Singapore have ramifications beyond
our shores. Singapore is an open economy and connected to the rest
of the world. It is a major international centre for trade, finance and
logistics. A cyber-attack on Singapore could potentially impact the
wider regional and global economy.
Singapore has to ensure that its CIIs are not just resilient against
physical threats, but also against cyber threats. A cyber-resilient
infrastructure will provide peace of mind to Singaporeans.
A cyber-resilient infrastructure will reinforce confidence in Singapore
as a resilient and trusted global centre of trade and commerce.
Strengthen our cybersecurity governance and legislative
framework. We will introduce a new Cybersecurity Act that will
require CII owners and operators to take responsibility for securing
their systems and networks. The Act will also facilitate the sharing
of cybersecurity information with and by CSA, and empower CSA
and sector regulators to work closely with affected parties to resolve
cybersecurity incidents in a timely manner.
Make Government systems more secure. The Government will
expand its efforts to secure its systems and networks. This includes
allocating 8 per cent of the total Government ICT expenditure to
cybersecurity. We will also reduce the attack surface of Government
systems, enhance cyber situational awareness in the government
sector and sharpen cyber incident management.